Количество 7
Количество 7
CVE-2025-64505
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.
CVE-2025-64505
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51.
CVE-2025-64505
LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index
CVE-2025-64505
LIBPNG is a reference library for use in applications that read, creat ...
SUSE-SU-2025:4432-1
Security update for libpng12
SUSE-SU-2025:4383-1
Security update for libpng12
SUSE-SU-2025:4436-1
Security update for libpng16
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-64505 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51. | CVSS3: 6.1 | 0% Низкий | 27 дней назад | |
CVE-2025-64505 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette indices. The vulnerability occurs when palette_lookup array bounds are not validated against externally-supplied image data, allowing an attacker to craft a PNG file with out-of-range palette indices that trigger out-of-bounds memory access. This issue has been patched in version 1.6.51. | CVSS3: 6.1 | 0% Низкий | 27 дней назад | |
CVE-2025-64505 LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index | CVSS3: 6.1 | 0% Низкий | 18 дней назад | |
CVE-2025-64505 LIBPNG is a reference library for use in applications that read, creat ... | CVSS3: 6.1 | 0% Низкий | 27 дней назад | |
SUSE-SU-2025:4432-1 Security update for libpng12 | 0% Низкий | 4 дня назад | ||
SUSE-SU-2025:4383-1 Security update for libpng12 | 0% Низкий | 9 дней назад | ||
SUSE-SU-2025:4436-1 Security update for libpng16 | 4 дня назад |
Уязвимостей на страницу